Sunday, 31 August, 2025
Attackers Exploit Velociraptor Forensic Tool to Create C2 Tunnel via VS Code

Cybersecurity experts have uncovered a sophisticated intrusion where attackers hijacked the legitimate forensic tool Velociraptor to gain remote access. Using msiexec, malware was staged from a Cloudflare Workers domain, installing Velociraptor. It then downloaded and launched Visual Studio Code with tunneling enabled—creating a covert command-and-control (C2) channel.
Read full story at The Hacker News